# Grok filter extracting fields from message

**URL:** <https://discuss.elastic.co/t/grok-filter-extracting-fields-from-message/238298>\
**Category:** Logstash\
**Created:** [June 23, 2020, 4:13pm UTC](https://discuss.elastic.co/t/grok-filter-extracting-fields-from-message/238298 "2020-06-23T16:13:48Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 23, 2020, 8:18pm UTC](https://discuss.elastic.co/t/grok-filter-extracting-fields-from-message/238298/8 "2020-06-23T20:18:12Z")

</div>

```
    dissect { mapping => { "message" => "%{ts} %{+ts} [%{thread}] %{loglevel} %{someField}{%{[@metadata][kvData]}}%{}" } }
    kv {
        source => "[@metadata][kvData]"
        field_split_pattern => ", "
    }

```

I changed the dissect to pull out the data between AuthenticationEvent{ and } into a separate field. That will result in

```
         "someField" => "c.c.d.c.s.a.UserAuthenticationListener - User logged in: AuthenticationEvent",
          "userName" => "username",
          "loglevel" => "INFO",
            "action" => "LOGIN",
         "userAgent" => "Chrome",
  "userAgentVersion" => "58.0.3029.110",
"productPermissions" => "bsg,rdm,dsm,catalog,helpdesk,policymanager,datadictionary,admin",
       "licenseType" => "CONSUMER",
     "failureReason" => "null",
           "timeout" => "1800000",
        "remoteHost" => "10.251.35.112",
         "timestamp" => "1592919002568",
         "sessionId" => "-303021888",
            "thread" => "https-jsse-nio-0.0.0.0-8443-exec-58",
                "ts" => "2020-06-23 15:30:02.568"
```

---

_[View the full topic](https://discuss.elastic.co/t/grok-filter-extracting-fields-from-message/238298)._
